what are the security implications?

Asked by Jeroen Hensing

check this post:
https://plus.google.com/u/0/102342595285863325267/posts/fugyhXhV61a

there's a whole discussion there with people about this package, who dont know if you sent back data to canonical, etc... i just thought i'd 'link' you in :).... probably not the best way..sorry..

Question information

Language:
English Edit question
Status:
Answered
For:
Ubuntu unity-scope-video-remote Edit question
Assignee:
No assignee Edit question
Last query:
Last reply:
Revision history for this message
actionparsnip (andrew-woodhead666) said :
#1

It's not spyware as your system is not uniquely identifiable. Once a blue moon this nonsense turns up. The search in Dash is sent to Amazon and results come back. Nothing more. No name, address, hostname, MAC address or anything else you can think of it is sent to Amazon so you are not identifiable.

Furthermore the feature is not only removable and optional by removing the shopping lens and rebooting, but it is also only in one of the 5 official versions of Ubuntu.

Revision history for this message
Thomas Krüger (thkrueger) said :
#2

Sorry Andrew, but your view on this is rather naive. The fact that there is no obvious ID included in the request does not make the user unidentifiable. In fact the IP address is enough to reduce the number of persons in question to one household, in most cases to just one.
The integration and activation of this function without explicit user permission is violating the German privacy laws, arguable even a violation of the German Penal Code. Most likely the laws of all EU nations due to EU law harmonization. The fact that it can be deactivated or uninstalled does not change that.

In other words: Yes, it is spyware, not the most aggressive type, but it is.

Revision history for this message
actionparsnip (andrew-woodhead666) said :
#3

We are not telling Amazon what you are searching for. Your anonymity is preserved because we handle the query on your behalf. Don’t trust us? Erm, we have root. You do trust us with your data already. You trust us not to screw up on your machine with every update. You trust Debian, and you trust a large swathe of the open source community. And most importantly, you trust us to address it when, being human, we err.

Unquote

Revision history for this message
actionparsnip (andrew-woodhead666) said :
#4

You send data to canonical not amazon. Canonical do not keep a database of searches and all amazon can do is keep a log of searches from the canonical server.

Not naive at all. Try knows what he is on about.

To reiterate, it's totally removable and kubuntu, xubuntu, lubuntu and medibuntu do not even use it.

Can you help with this problem?

Provide an answer of your own, or ask Jeroen Hensing for more information if necessary.

To post a message you must log in.